Little Orbit · Little Orbit Gfac · CVE-2026-12167
**Name of the Vulnerable Software and Affected Versions**
Little Orbit GFAC (affected versions not specified)
**Description**
The driver `GFAC Sys x64.sys` contains a communication port that lacks appropriate access restrictions, allowing a local attacker to access privileged driver functionality. Additionally, the driver is susceptible to a NULL pointer dereference—a condition where the software attempts to read from a memory address that is null—which can be triggered by crafted requests to cause a system crash and a denial of service.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.